🚨 Bonfire (BonfireSwap) - Loss ~$47K (2026-09-15)
Token: $BONFIRE
Network: BNB Chain
Type: Access Control / Approval Drain
The BonfireSwap router (0x17e8...03d3) exposes transfer(address to, uint amountAIn, address beneficiary, uint deadline) which calls _safeTransferFrom(tokenAddress, to, pancakePair, amountAIn) with no check that msg.sender owns or is authorized to spend `to`'s tokens. Any caller can therefore spend the BONFIRE approval any holder previously granted to the router: the attacker looped this (and skimPool) over ~65 holders who had approved BonfireSwap, force-selling their tokens into the Pancake pair and skimming the WBNB proceeds to their own contract (0x28E9...2127), extracting ~66 BNB (~$47K). Same arbitrary-source flaw exists in loggedTransfer/simpleTransfer.
TX: https://bscscan.com/tx/0xb4c00e8f3ba815b6c70f45026f8794d2c1f079646a89919077688ce60692193f
Attacker: https://bscscan.com/address/0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a
Victim: https://bscscan.com/address/0x17e801e17cefc6334059189c178d4783830e03d3
X: https://x.com/bonfiretoken
@defimon_subscription_bot
Post #3306
831
Forwarded from Defimon Signals
- ❤ 1